VYPR

Amelia Booking

by WordPress

CVEs (1)

  • CVE-2026-2931HigMar 26, 2026
    risk 0.57cvss 8.8epss 0.00

    The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes…